Version Affected: SecureAuth Identity Platform 22.02+
Overview
When using FIDO2 as a multi-factor authentication (MFA) method, users receive: "Authentication could not be completed. Please try again or choose another authentication method." A hardware security key such as a Yubikey enrolled for FIDO2 may instead show "This security key doesn't look familiar."
Cause
There can be various reasons for this error. One common cause is that the fully qualified domain name (FQDN) the user used to enroll their security key does not match the FQDN of the realm they are authenticating against -- for example, enrolling at https://company.domain.com/SecureAuthxx but authenticating against an alias such as https://alias-for-my-company.domain.com/SecureAuthxx.
Resolution
To use security keys successfully, make sure the realm's FQDN is the same FQDN that was used when the device was enrolled.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.